1. WLAN
Click Configure > WLANs on the left and then click the + sign to add a new WLAN. Configure with:
- Name (SSID): Guest WiFi (or whatever you wish)
- Primary Usage: Guest
- Forwarding Mode: Tunnel
Click Next and configure with:
- VLAN: 1 (or whatever you use)
Click Next and configure with:
- Is this WLAN for internal or guest?: Guest
Click Next and configure with:
- Captive Portal Type: ClearPass or other external Captive Portal
Under Auth servers click + then + again to create a new server. Configure with:
- Server type: RADIUS
- Name: Flame
- IP Address: 34.243.101.199
- Auth port: 1812
- Accounting port: 1813
- Shared key: <provided by Flame>
- Retype key: as above
- Timeout: 5
Click Submit and then configure the further options with:
- Host addressing: IPv4
- Host: cwp.flameanalytics.com
- Page: <provided by Flame>
Click Next and then Next again to complete the wizard.
2. Firewall
Next, click Roles & Policies on the left. Select the Aliases tab and click +. Configure with:
- IP Version: IPv4
- Name: guestwifi
Under Items click + and add the required domains as per below.
- Rule Type: Name
- Domain Name: cwp.flameanalytics.com
Click + again and do the same for all required domains:
Twitter / X
Click Submit to save.
3. Captive portal and RADIUS
Next, click Authentication on the left. Select the L3 Authentication tab and then click the Guest WiFi-cppm_prof entry. Configure with:
- Default Role: guest
- Default Guest Role: guest
- Redirect Pause: 0
- User Login: Enabled
- Guest Login: Disabled
- Logout popup window: Disabled
- Use HTTP for authentication Enabled
- Logon wait minimum wait: 1
- Logon wait maximum wait: 10
- Authentication Protocol: PAP
- Login page: <provided by Flame>
- Welcome page: <provided by Flame>
- Show Welcome page: Enabled
- Add switch IP in redirection URL: Enabled
- Adding APs MAC address in redirection URL: Enabled
- White List: Add guestwifi from the list
Click Submit to save, Next, select the AAA Profiles tab and click on Guest WiFi-aaa_prof. Configure with:
- Initial role: Guest WiFi-guest-logon
- RADIUS Interim Accounting: Enabled
Click Submit to save. Next, click on the RADIUS Accounting Server Group and configure with:
- RADIUS Accounting Server Group: Guest WiFi-dot1_svg
Click Submit to save. Next, select the Auth Servers tab and then All Servers > guest1. Leave all settings as they are except:
- Mode: Enabled
- MAC address delimiter: Dash
- Station ID Type: AP MAC address
- Station ID Delimiter: Dash
- Include SSID: Enabled
Click Submit to save.
Finally, click Pending Changes at the top and apply changes.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article